CVE-2022-36267
CVSS v3
9.8
CRITICAL
EPSS Score
54.5 %
exploit probability, as of 2026-10-05
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.
Technical details
- Published
- 2022-08-08
- Exploit-DB
- EDB-51011
Frequently asked questions
What is CVE-2022-36267?
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.
Is CVE-2022-36267 actively exploited?
Active exploitation of CVE-2022-36267 has not been confirmed. Its EPSS score was 54.5% on 2026-10-05, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2022-36267?
CVE-2022-36267 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2022-36267 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2022 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).